CVE-2017-0273
published 2017-05-12CVE-2017-0273: The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB…
PriorityP431medium5.9CVSS 3.0
AVNACHPRNUINSUCNINAH
EPSS
6.09%
92.6th percentile
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280.
Affected
18 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_10 | — | — |
| microsoft | windows_server_2008 | — | — |
| microsoft | windows_server_2012 | — | — |
| microsoft_corporation | server_block_message_1.0 | — | — |
| msrc | windows_10 | — | — |
| msrc | windows_10_version_1511 | — | — |
| msrc | windows_10_version_1607 | — | — |
| msrc | windows_10_version_1703 | — | — |
| msrc | windows_7 | — | — |
| msrc | windows_8.1 | — | — |
| msrc | windows_rt_8.1 | — | — |
| msrc | windows_server_2008 | — | — |
| msrc | windows_server_2008_r2 | — | — |
| msrc | windows_server_2012 | — | — |
| msrc | windows_server_2012_r2 | — | — |
| msrc | windows_server_2016 | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:N/I:N/A:P
vendor_msrc8.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-g5w5-8h24-v8qp: The Microsoft Server Message Block 1
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2017-0269 [MEDIUM] CWE-20 GHSA-g5w5-8h24-v8qp: The Microsoft Server Message Block 1
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0273 and CVE-2017-0280.
GHSA
GHSA-fvp7-487q-7m8q: The Microsoft Server Message Block 1
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2017-0273 [MEDIUM] CWE-20 GHSA-fvp7-487q-7m8q: The Microsoft Server Message Block 1
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0280.
GHSA
GHSA-m852-pj36-5xhg: The Microsoft Server Message Block 1
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2017-0280 [MEDIUM] CWE-20 GHSA-m852-pj36-5xhg: The Microsoft Server Message Block 1
The Microsoft Server Message Block 1.0 (SMBv1) allows denial of service when an attacker sends specially crafted requests to the server, aka "Windows SMB Denial of Service Vulnerability". This CVE ID is unique from CVE-2017-0269 and CVE-2017-0273.
Microsoft
Windows SMB Denial of Service Vulnerability
vendor_msrc·2017-05-09·CVSS 8.1
CVE-2017-0273 [MEDIUM] Windows SMB Denial of Service Vulnerability
Windows SMB Denial of Service Vulnerability
Description: A denial of service vulnerability exists in the Microsoft Server Block Message (SMB) when an attacker sends specially crafted requests to the server. An attacker who exploited this vulnerability could cause the affected system to stop responding until it is manually restarted. To attempt to exploit this issue, an attacker would need to send specially crafted SMB requests to the target system.
Note that the denial of service vulnerability would not allow an attacker to execute code or to elevate their user rights, but it could cause the affected system to stop accepting requests.
The security update addresses the vulnerability by correcting the manner in which SMB handles specially crafted client requests.
Windows SMB Server: Window
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Code Execution Vulnerability in LabVIEW
blogs_talos·2017-08-29·CVSS 9.3
[CRITICAL] Vulnerability Spotlight: Code Execution Vulnerability in LabVIEW
## Vulnerability Spotlight: Code Execution Vulnerability in LabVIEW
Vulnerability discovered by Cory Duplantis of Cisco Talos. Update : 9/1/17 - National Instruments has published the following advisory
## Overview
LabVIEW is a system design and development platform released by National Instruments. The software is widely used to create applications for data acquisition, instrument control and industrial automation. Talos is disclosing the presence of a potential code execution vulnerability which can be triggered by opening specially crafted VI files, the proprietary file format used by LabVIEW.
## TALOS-2017-0273 code execution vulnerability (CVE-2017-2779)
The VI file format describes various systems implemented in LabVIEW. Although there is no published specification for the file
Talos
Microsoft Patch Tuesday - May 2017
blogs_talos·2017-05-10·CVSS 7.5
CVE-2017-0290 [HIGH] Microsoft Patch Tuesday - May 2017
Today, Microsoft has release their monthly set of security updates designed to address vulnerabilities. This month's release addresses 56 vulnerabilities with 15 of them rated critical and 41 rated important. Impacted products include .NET, DirectX, Edge, Internet Explorer, Office, Sharepoint, and Windows.
In addition to the coverage Talos is providing for the normal monthly Microsoft security advisories, Talos is also providing coverage for CVE-2017-0290, the MsMpEng Malware Protection service vulnerability in Windows reported by Natalie Silvanovich and Tavis Ormandy of Google Project Zero. Snort rule SIDs for this specific vulnerability are 42820-42821.
## Vulnerabilities Rated Critical The following vulnerabilities are rated critical by Microsoft:
- CVE-2017-0221
- CVE-2017-0222
- CV
http://www.securityfocus.com/bid/98274http://www.securitytracker.com/id/1038433https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0273http://www.securityfocus.com/bid/98274http://www.securitytracker.com/id/1038433https://ics-cert.us-cert.gov/advisories/ICSMA-18-058-02https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2017-0273
2017-05-12
Published